Skip to content
This repository was archived by the owner on Jun 24, 2025. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .changeset/cuddly-eggs-juggle.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
---
"@tern-secure/nextjs": patch
---

refactor: Simplify TernSecure middleware and error handling

- Remove unused imports and error classes
- Modify route matching regex pattern
- Streamline authentication middleware logic
- Add Edge runtime support
- Improve error redirection and handling
- Clean up response headers
55 changes: 24 additions & 31 deletions src/server/ternSecureMiddleware.ts
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
import { type NextRequest, NextResponse } from 'next/server';
import type { UserInfo } from './types'
import { TernSecureError } from '../errors';


export const runtime = "edge"

interface Auth {
user: UserInfo | null
Expand All @@ -22,11 +21,9 @@ type MiddlewareCallback = (
export function createRouteMatcher(patterns: string[]) {
return (request: NextRequest): boolean => {
const { pathname } = request.nextUrl
return patterns.some(pattern => {
return patterns.some((pattern) => {
// Convert route pattern to regex
const regexPattern = new RegExp(
`^${pattern.replace(/\*/g, '.*').replace(/\((.*)\)/, '(?:$1)?')}$`
)
const regexPattern = new RegExp(`^${pattern.replace(/\*/g, ".*").replace(/$$(.*)$$/, "(?:$1)?")}$`)
return regexPattern.test(pathname)
})
}
Expand All @@ -53,44 +50,40 @@ export function ternSecureMiddleware(callback: MiddlewareCallback) {
if (currentPath !== '/sign-in') {
const redirectUrl = new URL('/sign-in', request.url)
redirectUrl.searchParams.set('redirect', currentPath)
throw new TernSecureError('UNAUTHENTICATED', redirectUrl.toString())
} else {
throw new Error('UNAUTHENTICATED')
throw new Error("UNAUTHENTICATED")
}
}
}
},
}

if (!callback) {
return NextResponse.next()
}


//if (!callback) {
// return NextResponse.next()
// }

if (callback){
try {
await callback(auth, request)
return NextResponse.next()
} catch (error) {
if (error instanceof Error && error.message === 'Unauthorized access') {
console.log('middleware: Unauthorized access, redirecting to sign-in')
return NextResponse.redirect(error.message)
// Handle authentication errors
if (error instanceof Error && error.message === "UNAUTHENTICATED") {
const redirectUrl = new URL("/sign-in", request.url)
redirectUrl.searchParams.set("redirect", request.nextUrl.pathname)
return NextResponse.redirect(redirectUrl)
}
// Re-throw other errors
throw error
}
}

} catch (error) {
console.error("Middleware error:", {
error:
error instanceof Error
? {
name: error.name,
message: error.message,
stack: error.stack,
}
: error,
path: request.nextUrl.pathname,
})
// Continue to the next middleware or route handler
const response = NextResponse.next()

// Clean up response
response.headers.delete("x-middleware-next")

return response
} catch (error) {
console.error("Middleware error:", error)
return NextResponse.redirect(new URL('/sign-in', request.url))
}
}
Expand Down